
nuguard
opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Some good resources for getting started with application security

OWASP Secure Agent Playbook Project

OWASP Certified Secure-Software Developer

OWASP Smart Contract Security (SCS) Project

Source code for the Binaries of OWASP WrongSecrets

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

Given JSON-like content, The JSON Sanitizer converts it to valid JSON.

Research repository documenting LLM generalization ceilings in code security vulnerability detection, with cross-evaluation across synthetic and…

OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).